- [2026.06.12]Before It Mines You, It Checks Whether You're Worth More: An SSH Botnet That Triages Hosts for Telegram Sessions and SIM-Box Fraud
A 16-node SSH botnet runs a nine-command triage script instead of dropping a miner — looking for Telegram Desktop session files, GSM modems, SMS spools, and SIM-management config, the hardware and data of SMS-fraud and 2FA-interception operations. It is a botnet that grades every host it lands on before deciding how to monetize it.
- [2026.06.12]The Honeypot-Detection Arms Race: Three Tiers of Checks Attackers Run Before They Trust Your Shell
Before they drop a payload, the better SSH botnets now ask whether they're standing in a honeypot. We captured three escalating tiers of that check on our sensors — from commodity CPU-core counting, to a seven-step environment-integrity routine, to a deep /proc-entropy and PID-reality battery we cannot find published anywhere. In every case the operator ran the checks and then proceeded to the payload. That last fact is the point.
- [2026.06.02]Residential Broadband Botnet Uses AsyncSSH to Validate Credentials Across Four Regions
98 compromised residential broadband hosts — all on two Vietnamese ISPs — ran a coordinated SSH credential-validation campaign across four geographically distributed sensor meshes over seven days. The same HASSH fingerprint, the same Python SSH library, zero successful logins: this is infrastructure reconnaissance, not exploitation.
- [2026.05.20]Outlaw/mdrfckr relay activity from Syrian institutional IP space
An IP address in a network block attributed to Syrian government services (AS29256) is relaying activity consistent with Outlaw/mdrfckr botnet propagation. We assess this as compromised infrastructure, not state-directed activity. Our distributed honeypot network captured the relay chain end-to-end: a three-tier SSH scanning pipeline, a modern exploitation tool advertising ML-KEM-capable key exchange, the mdrfckr SSH key injection, and a 23-second automated burst of 18 reconnaissance commands. This is not new malware research. It is a field observation showing how old commodity botnets continue to exploit weak SSH hygiene and can quietly turn institutional infrastructure into relay nodes.
- [2026.05.14]Watcher-NetAI / skn: a Linux SSH botnet, with the scanner half-open [Part 1/2]
An SSH-delivered Linux kit observed on two honeypot sensors drops a non-root systemd-user persistence unit, then runs a 10 MB Go scanner with intact DWARF: source tree, module name skn, capability map (scanner, SOCKS5, password-change cascade with VyOS fallback, embedded HTTP listener) all visible. The loader is hardened; the scanner is not. Stage-2 C2 on connexionlost.{net,zip} → 194.5.97.46.
- [2026.05.14]Watcher-NetAI / skn - Detection Brief [Part 2/2]
Single-page SOC-facing summary of the Watcher-NetAI / skn cluster - top IOCs, four triage-priority hunts, links to the YARA / Sigma / IOC bundles, controlled-sharing contact. Full analysis in the main report.
- [2026.05.06][Part 2/2] Two-Way Prometei: When the Linux Botnet Pivots Back to Windows
17 Windows modules dropped alongside the Linux ELF in the same Prometei drop, including a Mimikatz variant frozen since 2023, a Tor stack masquerading as MSDTC and Smart Card services, and a Linux ELF that pivots back to Windows via WinRM (5985), Redis SLAVEOF (16379), and SMBv1-era dialects. One cross-platform toolkit, walker.ini glue, server-side fingerprint of the C2.
- [2026.05.06][Part 1/2] Prometei Goes Both Ways: Same C2, Both Operating Systems, Three Months Apart
A fresh Prometei v3/v4 ELF on a Linux honeypot, beaconing to the same C2 IP, Tor onion, and UPlugPlay disguise convention eSentire flagged on the Windows side three months earlier. The JSON-trailer schema yields a parent-peer back-pointer per bot. Postscript: four parallel binary-churn cadences in the same toolkit, including bit-identical zsvc unpacked code across drops.
- [2026.05.04]Turf Wars at Scale: Botnets Fighting for the Same Servers
42 post-auth payload deployments from 13 coordinated IPs on AS51396 over 58 hours. The eviction script that precedes each install maps the contested-infrastructure reality: Diicot self-eviction, XMRig, CNRig, Rete, and Kinsing artifacts competing on the same pools of exposed servers.